The Dutch findings show also that concerns about adversarial manipulation and a shortage of AI skills are shaping how Dutch organisations adopt and govern AI. Resilience increasingly depends on managing dependencies, securing data and AI, and building the skills and cyber culture needed to use new technologies responsibly.
PwC's Global Digital Trust Insights (DTI) is one of the largest and longest-running annual surveys on cybersecurity, capturing the views of 3,934 business and technology leaders across 71 countries. The 2027 edition examines how organisations are managing cybersecurity in a rapidly evolving digital environment, shaped by simultaneous shifts in technology, threats and geopolitics.
The Dutch and Western European results reveal how global pressure translates into distinct regional priorities, investment choices and challenges. Together, these bring resilience to the foreground.
Mimoent Haddouti, partner cyber, data, technology & risk at PwC Netherlands: ‘The question is increasingly not just how secure your organisation is, but how resilient it is when critical operations depend on complex supply chains, rapidly changing technology and increasingly autonomous AI.’
The Dutch findings are based on respondents from a broad range of sectors and organisation sizes. Because of the small base size compared with the global DTI, the results should be treated as indicative rather than statistically representative of Dutch organisations.
Dutch investment priorities tell a partly familiar story, aligning with global peers on most fronts while diverging on others.
Which of the following areas of your organisation’s cyber strategy are changing in response to the current geopolitical landscape over the next 12 months?
Third-party and supply-chain risk management rank first at 61 per cent, followed by threat intelligence, geopolitical monitoring and collaboration at 52 per cent, and data governance and localisation at 45 per cent. These priorities are connected: operational resilience increasingly depends on service providers, the jurisdictions in which data and technology are governed, and the ability to anticipate disruption across the wider ecosystem.
Third-party risk is not only a procurement or compliance issue. Organisations can outsource services and processes but retain accountability for continuity. A supplier holding privileged access, integration credentials or a critical operational role can become both an attack route and a concentration point. The strategic response is to connect supplier governance with architecture, continuity planning, incident response and recovery testing.
Data governance and localisation are another notable feature of the Dutch results. Where important services or data depend on providers operating under different jurisdictions, third-party risk, regulatory obligations and digital sovereignty converge. Threat intelligence and geopolitical monitoring reinforce the same message: organisations need visibility not only of direct cyber threats, but also of dependencies and policy changes that can alter their exposure.
Dutch respondents also rank threat intelligence and geopolitical monitoring highly (52%). Political instability has moved geographically closer to Europe, while reliance on US-based third parties compounds uncertainty about technology and trade alliances. The Netherlands has a dense geopolitical exposure profile for a country of its size, including internet and data-exchange infrastructure of continental significance, one of Europe’s largest ports, international judicial institutions in The Hague and a semiconductor supply chain at the centre of export-control measures.
Compared with respondents globally and in Western Europe, Dutch respondents place relatively less emphasis on revising cyber insurance, incident response and crisis management plans (33%), as well as on the location, resilience and redundancy of critical infrastructure (33%). One possible explanation is that these topics are already receiving sustained attention through sectoral supervision and preparations for DORA, NIS2 and Dutch resilience legislation. At European level, DORA, NIS2, the Cyber Resilience Act and the AI Act have increased expectations around cyber resilience. Domestically, the ‘Cyberbeveiligingswet’ (Cbw) and the ‘Wet weerbaarheid kritieke entiteiten’ (Wwke) have kept resilience and incident preparedness high on the agenda.
Which of the following factors are influencing your cyber spend priorities over the next twelve months?
Data protection/data trust (55%) and securing AI and autonomous agents (55%) share the top position among Dutch respondents. Their joint ranking suggests that organisations are prioritising both the information that underpins digital operations and the emerging technologies that increasingly use and act on it. Data protection sits at the intersection of digital sovereignty, third-party risk and competitive value, while the focus on AI and autonomous agents points to growing attention to the security and governance requirements that accompany their adoption.
Dutch respondents are paying attention to AI-enabled cyberattacks, but their focus is primarily on risks that organisations can influence directly. Securing against AI-enabled attacks is a priority for 36 per cent of respondents. This includes familiar threats that are taking on a new dimension because of AI, such as phishing, social engineering, identity fraud and deepfakes in payment and onboarding processes.
Geopolitical developments are also high on the agenda for Dutch organisations. This is reflected not only in their priorities but also in their budgets. Organisations are allocating funds to threat intelligence, supplier diversification and redundancy. Geopolitical uncertainty is therefore translating into concrete measures to reduce dependencies on suppliers and supply chains.
Preparing for quantum computing risks, by contrast, has yet to become a major corporate spending priority: just twelve per cent of Dutch respondents identify this as an area of focus. This is notable given that the Netherlands is investing in quantum research and has developed guidelines for the transition to post-quantum cryptography. These national developments have not yet translated into a corresponding investment priority among businesses.
What is preventing your organisation from increasing AI agent autonomy for security operations?
Dutch respondents are not yet granting autonomy to agents in security operations. The primary constraint is adversarial manipulation of AI systems (52%), whereas Global and Western Europe rank reliability and maturity of current AI technology first (55%), the latter still being a relevant area of concern for Dutch respondents (48%). This points to demand for capabilities such as red-teaming AI systems, prompt injection defence, agent behaviour monitoring and adversarial testing in CI/CD.
‘AI adoption in security is increasingly shaped not only by the maturity of the technology, but also by an organisation’s ability to access and develop the right expertise,’ says Haddouti. ‘It is therefore essential to ensure that employees are AI-literate and to invest in the knowledge and skills they need to use AI effectively and responsibly. Investing in these capabilities is just as important as investing in the technology itself.’
The contrast is sharp: elsewhere the brake on autonomy is the technology; for the Dutch it is the adversarial and people factors. Dutch respondents are less concerned about technology maturity, accountability and explainability, and more concerned about adversarial manipulation and skills gaps.
Dutch respondents also seem to view AI chiefly as an internal capability to be secured and governed, while regarding AI-enabled attacks as an extension and intensification of threats they already face, such as phishing, fraud and social engineering, rather than as a separate strategic priority.
Which of the following strategies are you prioritising over the next 12 months to support the professional development and retention of your cybersecurity talent?
While Global and Western Europe place providing growth opportunities first, Dutch respondents prioritise supporting a strong cyber culture (61%), followed by investing in AI-enabled tools and training people to work alongside them (58%), and monitoring workload balance and burnout (42%). They place much less emphasis on pay as a retention lever (15% vs 40% Global).
This compensation gap is not an isolated HR matter: governing third-party risk (61%), securing AI agents (55%) and closing the AI-oversight skills gap (48%) are all skills-intensive objectives that technology cannot substitute. Attrition therefore lands on the profiles needed to execute these priorities, in a market where organisations, service providers and big tech compete for the same pool.
Subscribe to our newsletter.
Partner cyber, data, technology & risk, PwC Netherlands
Mimoent has extensive experience in cybersecurity, data, technology and risk management within complex and highly regulated environments. She advises organisations at a strategic level on digital resilience, technology dependencies, compliance and digital sovereignty.
+31 (0)6 20 54 72 49